Aller au contenu

Fiche vulnérabilité

CVE-2021-25263 : faille élevée yandex yandex browser (CVSS 7.8)

Description

Local privilege vulnerability in Yandex Browser for Windows prior to 21.9.0.390 allows a local, low privileged, attacker to execute arbitary code with the SYSTEM privileges through manipulating files in directory with insecure permissions during Yandex Browser update process.

En bref

Sévérité
Élevée (CVSS 7.8)
Vecteur CVSS
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
17 août 2021
Dernière mise à jour
17 juin 2026

Produits concernés

  • yandex yandex browser

Références

Rechercher une autre vulnérabilité dans la base CVE